CVE-2024-31903: IBM Sterling B2B Integrator Standard Edition code execution
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
Other sources
IBM Sterling B2B Integrator Standard Edition allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31903?
CVE-2024-31903 is considered a critical vulnerability due to the potential for remote code execution on vulnerable systems.
How do I fix CVE-2024-31903?
To fix CVE-2024-31903, upgrade IBM Sterling B2B Integrator Standard Edition to version 6.2.0.3 or later.
What versions are affected by CVE-2024-31903?
CVE-2024-31903 affects IBM Sterling B2B Integrator Standard Edition versions 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2.
Can CVE-2024-31903 be exploited remotely?
Yes, CVE-2024-31903 can be exploited by attackers on the local network to execute arbitrary code.
What is the cause of CVE-2024-31903?
CVE-2024-31903 is caused by the deserialization of untrusted data in vulnerable versions of the software.